HomeLegalPrivacy Policy
DPDP Act 2023 • GDPR Ready • CERT-In Compliant

HostAsia Privacy Policy & Data Protection

This statutory Privacy Policy governs how HostAsia Cloud Technologies collects, uses, encrypts, and retains customer and subscriber data in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, CERT-In Directives, and international privacy standards.

Effective Date: September 29, 2026
Document Version: v2.4 (Regulatory Update)
Jurisdiction: Kolkata, West Bengal, India
Regulatory Certifications & Standards:
India DPDP Act 2023CERT-In Log CompliantEU GDPR (2016/679)ICANN • NIXI .IN AccreditedPCI-DSS Level 1 Gateway
Clause 1

1. Corporate Scope & Identification of Data Fiduciary

This Privacy Policy forms an integral and legally enforceable agreement between you (the "User", "Subscriber", "Customer", or "Data Principal") and HostAsia Cloud Technologies (hereinafter referred to as "HostAsia", "we", "us", or "our"), having its registered server infrastructure and principal operations in Mumbai, Maharashtra, India.

Under the Digital Personal Data Protection Act, 2023 (DPDP Act), HostAsia acts as a Data Fiduciary in respect of your account identity, billing records, and subscriber profile. For customer server data, virtual machines, database contents, and email hosting stored by you on our cloud infrastructure, HostAsia operates as a Data Processor, processing such data solely upon your configuration and instruction.

Platforms Covered by this Policy:

This Policy applies unconditionally to our primary portal (hostasia.in), international website (hostasia.com), Client Billing Panel (userpanel.hostasia.in), SuperAdmin consoles, automated provisioning APIs (/api/v1), and all associated bare-metal, VPS, cloud hosting, and domain registration modules.

Clause 2

2. Legal & Regulatory Compliance Framework

HostAsia operates under strict adherence to Indian and international statutory standards, including:

DPDP Act, 2023 (India)

Statutory adherence to fair processing, explicit notice, purpose limitation, parent/guardian consent verification for minors, and automated data breach notifications to the Data Protection Board of India.

CERT-In Directions (April 2022)

Under Indian Computer Emergency Response Team directives, VPS, Cloud, and Hosting providers are mandated to maintain subscriber records and IPv4/IPv6 assignment access logs for a mandatory minimum of 5 years.

IT Act, 2000 & SPDI Rules

Implementation of reasonable security practices, ISO/IEC 27001 parity, cryptographic storage, and designated statutory Grievance Officer compliance under Rule 5(9).

EU GDPR & International Standards

For citizens of the European Economic Area (EEA), HostAsia adheres to Standard Contractual Clauses (SCCs), lawful basis definitions under Article 6, and transparent data subject rights.

Clause 3

3. Categories of Personal Data Collected

We collect and hold personal information only where necessary to provision cloud infrastructure, combat fraud, and fulfill statutory tax and telecom record-keeping obligations:

Data CategorySpecific Data Attributes Collected
Identity & Account DataFull legal name, email address, mobile/WhatsApp phone number, physical billing address, state/province, country, and salted bcrypt/argon2 password hashes.
Commercial & Tax DataCompany/Entity name, GST Identification Number (GSTIN), PAN (where statutory deduction applies), and verified electronic invoicing addresses.
Technical & Telemetry DataClient originating IP address, browser User-Agent header, operating system fingerprint, API authorization keys (ha_live_...), and session authentication timestamps.
Server Infrastructure LogscPanel, WHM, and Virtualizor control panel logins, SSH console access timestamps, IP allocation assignments, reverse DNS entries, and SMTP relay transaction logs.
Domain Registration RecordsRegistrant Name, Organization, Postal Address, Phone Number, and Administrative/Technical Contact details mandated by ICANN and Registry operators (e.g., NIXI for .IN).
What HostAsia NEVER Collects or Stores:We never inspect, read, or monetize private website source code, database tables, or private SSH keys hosted within your containers or VPS. We never store raw credit/debit card numbers, CVVs, or NetBanking PINs on our servers.
Clause 5

5. Domain Registration, ICANN, NIXI & WHOIS Protocols

When you register, renew, or transfer a top-level domain (TLD) through HostAsia:

1. Registry Escrow & Transfer: ICANN (Internet Corporation for Assigned Names and Numbers), registry operators (e.g. NIXI for .IN, Verisign for .COM), and upstream registrar partners (such as Spaceship / Namecheap) require registrant contact information for legal ownership validation and Registry Data Escrow (RDE).

2. WHOIS Privacy Protection: Where supported by the respective TLD registry, HostAsia enables free WHOIS Privacy Protection by default. Your personal phone number, physical address, and personal email are replaced with a proxy privacy alias in public RDAP/WHOIS directories.

3. Registry Exceptions: Certain country-code TLDs (such as .IN, .CO.IN, .US) have statutory registry policies that prohibit masking or require designated local contact verification under applicable national registry mandates.

Clause 6

6. Payment Processing & PCI-DSS Financial Handling

HostAsia operates under strict tokenized payment protocols:

  • PCI-DSS Compliant Aggregators: Financial payments (UPI, RuPay, Visa, Mastercard, NetBanking, PayPal, International Cards) are handled directly through certified PCI-DSS Level 1 payment gateways (Razorpay, Stripe, PayPal).
  • Zero Raw Card Storage: HostAsia’s database stores only the masked card suffix (e.g. Ending in 4242), the cardholder's bank name, transaction reference IDs, and payment statuses. No CVV or card PIN ever traverses or resides on our application servers.
  • Statutory Invoicing: Tax invoices featuring your GSTIN, HSN/SAC codes (998315 for web hosting), state supply codes, and calculated CGST/SGST/IGST are archived for seven (7) financial years pursuant to the Central Goods and Services Tax (CGST) Act, 2017.
Clause 7

7. Datacenter Infrastructure & Technical Security Measures

Your data is housed in enterprise-grade, certified facilities with multi-layered perimeter and cryptographic protections:

Mumbai, India (Primary)Tier-4 Certified facility, biometric access control, 24/7 armed security, dual power feeds.
Singapore (APAC Hub)Equinix SG1 / Global Switch facility, ISO 27001, SOC 2 Type II, low-latency regional connectivity.
Frankfurt, GermanyGDPR-compliant European node with 100% green energy sourcing and direct DE-CIX peering.

Technical Defenses Deployed:

  • End-to-end TLS 1.3 encryption across all client portal dashboards and administrative endpoints.
  • AES-256 cryptographic encryption for database backups, API secrets, and sensitive credentials.
  • Automated edge Anti-DDoS rate-limiting and SYN flood scrubbing mitigating up to 1.2 Tbps attacks.
  • Strict Role-Based Access Control (RBAC) ensuring internal staff only access telemetry upon authorized support ticket escalations.
Clause 8

8. Cookies & Browser Telemetry Policy

We use cookies and browser local storage strictly to ensure optimal operational functionality:

1. Strictly Necessary Cookies:Preserving your shopping cart items (hostasia_cart), selected currency preference (hostasia_currency), active JWT session tokens, and CSRF protection security headers.
2. Affiliate Attribution Cookies:Tracking referral identifiers (hostasia_aff) for 30 days to credit registered partners under the HostAsia Affiliate Program.
3. Cookie Control & Disabling:You can restrict or block cookies through your browser settings. However, disabling essential cookies will prevent authentication into the client portal and shopping cart checkout.
Clause 9

9. Data Retention & Erasure Schedules

HostAsia retains personal data only as long as necessary to fulfill service provisioning or comply with statutory retention laws:

Data Record TypeRetention PeriodStatutory Justification
Active Account ProfileDuration of active subscription + 180 days post-terminationAccount recovery and service continuity.
Server & IP Access Logs5 Years (Mandatory)CERT-In Directives (Govt of India mandate).
Financial Tax Invoices7 Financial YearsIndian GST Act & Income Tax Act, 1961.
Support Ticket Transcripts3 Years from resolutionQuality assurance and contractual dispute resolution.
Terminated VPS BackupsPurged after 7 daysAutomatic disk shredding post-grace period.
Clause 10

10. Your Statutory Rights as a Data Principal

Under the DPDP Act, 2023 and the GDPR, you possess the following actionable rights regarding your personal information:

1. Right to Access & Summary:You can request a complete digital export of all personal data, contact information, and service history held by HostAsia.
2. Right to Correction / Rectification:You can immediately update outdated phone numbers, email addresses, or company details via the Client Dashboard or by submitting a ticket.
3. Right to Erasure ("To Be Forgotten"):Subject to mandatory statutory tax and CERT-In logging periods, you may request complete account deletion upon termination of active services.
4. Right to Nominate:Pursuant to Section 14 of the DPDP Act, you have the right to nominate an individual to exercise your privacy rights in the event of death or incapacity.

To exercise any of these rights, email our Grievance Desk at privacy@hostasia.in using your verified registered account email address.

Clause 11

11. Law Enforcement, CERT-In & Subpoena Guidelines

HostAsia maintains a strict, transparent protocol regarding requests from law enforcement agencies, cyber cells, and statutory judicial bodies:

1. Mandatory Legal Process: We do not disclose subscriber telemetry or customer information to any third party or governmental entity without a formal, legally verified written request issued under Section 91 of the CrPC, a formal directive from CERT-In, or a valid order signed by a competent judicial magistrate in India.

2. Emergency Imminent Harm Exception: In bona fide emergencies involving imminent physical danger, child sexual abuse material (CSAM), or critical national security emergencies, HostAsia will cooperate with designated cyber investigation authorities within statutory parameters.

3. Customer Notification: Unless strictly prohibited by statutory gag order, non-disclosure order, or sealed court directive, HostAsia aims to notify affected subscribers of legal data demands relating to their accounts.

Clause 12 • Statutory Notice

12. Statutory Grievance Redressal & Data Protection Officer (DPO)

In compliance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and Section 8(9) of the Digital Personal Data Protection Act, 2023, the designated statutory officer for HostAsia is:

Designation:Grievance & Data Protection OfficerHostAsia Cloud Technologies
Dedicated Privacy Inbox:privacy@hostasia.inAlt: grievance@hostasia.in
Statutory SLA Response Time:Acknowledgment within 72 HoursFinal resolution within statutory 30 days
Registered Operational Base:Comfort Space, 28/A Rafi Ahmed Kidwai Road, 02nd Floor, Kolkata 700016, India
If you are not satisfied with our redressal, you retain the legal right to lodge a formal complaint with the Data Protection Board of India.